Vendor
critical
threat
TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376
2 rules 9 TTPs 3 CVEs 7 IOCsRussia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.
PoC
Zimbra Collaboration Suite +10
TA488
+2
espionage
xss
zimbra
apt
state-sponsored
half-click
cve-2025-66376
2r
9t
3c
7i
updated
high
threat
CVE-2026-8851: SOGo SQL Injection Vulnerability in ACL Management
2 rules 3 TTPs 1 CVESOGo 5.12.7 is vulnerable to SQL injection in the Access Control List management functionality, allowing authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint, which can be exfiltrated via the /acls API.
SOGo 5.12.7
sql-injection
cve-2026-8851
data-exfiltration
2r
3t
1c